Files
Mic92 003af33155
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
fix clan-core update
2025-10-14 13:20:29 +01:00

166 lines
4.2 KiB
Nix

{
pkgs,
config,
lib,
...
}:
let
cfg = config.services.samba;
sharedFolders = {
B4L.users = [
"berwn"
"janik"
"arjen"
"w"
"b4l-service"
];
GLOM.users = [ "berwn" ];
};
in
{
options.services.samba.sambaUsers = lib.mkOption {
type = lib.types.attrsOf (
lib.types.submodule {
options = {
createUser = lib.mkOption {
type = lib.types.bool;
default = true;
description = "Whether to create a system user for this samba user";
};
};
}
);
default = { };
description = "Samba users to create passwords for";
};
config = {
services.samba = {
enable = true;
package = pkgs.samba;
openFirewall = true;
settings = {
global = {
security = "user";
workgroup = "WORKGROUP";
"server string" = "Storiantor01";
interfaces = "eth* en*";
"max log size" = "50";
"dns proxy" = false;
"syslog only" = true;
};
}
// lib.mapAttrs (share: opts: {
path = "/mnt/hdd/samba/${share}";
comment = share;
"force user" = share;
"force group" = share;
public = "yes";
"guest ok" = "no";
#"only guest" = "yes";
"create mask" = "0640";
"directory mask" = "0750";
writable = "yes";
browseable = "yes";
printable = "no";
# TODO
"valid users" = toString opts.users;
}) sharedFolders
// lib.mapAttrs (user: opts: {
comment = user;
path = "/mnt/hdd/samba/${user}";
"force user" = user;
"force group" = "users";
public = "yes";
"guest ok" = "no";
#"only guest" = "yes";
"create mask" = "0640";
"directory mask" = "0750";
writable = "yes";
browseable = "yes";
printable = "no";
"valid users" = user;
}) cfg.sambaUsers;
};
# Configure samba users
services.samba.sambaUsers = {
backup = { };
arjen = { };
janik = { };
berwn = { };
b4l-service = { };
};
users.users = {
# B4L
backup.isNormalUser = true;
backup.extraGroups = [ "samba" ];
arjen.isNormalUser = true;
arjen.extraGroups = [ "samba" ];
janik.isNormalUser = true;
janik.extraGroups = [ "samba" ];
berwn.extraGroups = [ "samba" ];
b4l-service.isNormalUser = true;
b4l-service.extraGroups = [ "samba" ];
}
// lib.mapAttrs (share: opts: {
isSystemUser = true;
group = share;
}) sharedFolders;
users.groups = lib.mapAttrs (share: opts: { }) sharedFolders;
clan.core.vars.generators = lib.mapAttrs' (
user: opts:
lib.nameValuePair "${user}-smb-password" {
files.password = { };
runtimeInputs = with pkgs; [
coreutils
xkcdpass
mkpasswd
];
script = ''
xkcdpass --numwords 3 --delimiter - --count 1 > $out/password
'';
}
) cfg.sambaUsers;
systemd.services.samba-smbd.postStart =
lib.concatMapStrings (
user:
let
password = config.clan.core.vars.generators."${user}-smb-password".files.password.path;
in
''
mkdir -p /mnt/hdd/samba/${user}
chown ${user}:users /mnt/hdd/samba/${user}
# if a password is unchanged, this will error
(echo $(<${password}); echo $(<${password})) | ${config.services.samba.package}/bin/smbpasswd -s -a ${user}
''
) (lib.attrNames cfg.sambaUsers)
+ lib.concatMapStrings (share: ''
mkdir -p /mnt/hdd/samba/${share}
chown ${share}:${share} /mnt/hdd/samba/${share}
'') (lib.attrNames sharedFolders);
services.samba-wsdd = {
enable = true;
openFirewall = true;
};
services.avahi = {
publish.enable = true;
publish.userServices = true;
# ^^ Needed to allow samba to automatically register mDNS records (without the need for an `extraServiceFile`
nssmdns4 = true;
# ^^ Not one hundred percent sure if this is needed- if it aint broke, don't fix it
enable = true;
openFirewall = true;
};
};
}